Cleartext – September 09, 2026
Wednesday, September 9, 2026·10:01
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – September 09, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 9 stories across 5 topic areas, including: Feds accuse China of ‘systematic’ distillation of U.S. AI models; Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours; France Establishes New Government-Focused Cyber Incident Response Unit.
Stories Covered
🌍 Geopolitical
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CyberScoop · Sep 08 · Relevance: █████████░ 9/10
Why it matters to CISOs: A joint CISA/NSA/FBI advisory declaring industrial-scale Chinese extraction of U.S. AI model capabilities signals escalating IP theft risk for enterprises deploying frontier AI—CISOs must assess whether their AI API usage and model access controls could be weaponized or monitored by adversaries.
- Chinese AI firms used large-scale knowledge distillation—routing millions of API requests across accounts—to extract capabilities from Claude, GPT, Gemini, and Grok
- Joint advisory from CISA, NSA, and FBI characterizes this as the 'core' of Chinese AI development strategy, not opportunistic theft
- Enterprises using U.S. frontier AI models through shared or public APIs may have inadvertently contributed data to this extraction pipeline
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
The Hacker News · Sep 08 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Google's Threat Intelligence Group documenting a financially motivated group using autonomous multi-agent AI frameworks to harvest thousands of credentials in under six hours represents a qualitative shift in attack velocity that outpaces traditional detection and response windows.
- Threat actors deployed an autonomous multi-agent attack framework that harvested thousands of credentials in fewer than six hours
- Google GTIG observed diverse-motivation adversaries targeting proprietary AI systems as both tools and targets
- Attack speed at this scale means traditional SOC triage cycles are structurally too slow—automated response controls are now a baseline requirement
France Establishes New Government-Focused Cyber Incident Response Unit
Infosecurity Magazine · Sep 08 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: France's Prime Minister standing up a dedicated government cyber incident response unit following a major attack on the national tax authority signals European governments escalating cyber as a national security priority—relevant context for CISOs navigating EU regulatory relationships and cross-border incident coordination.
- A major cyberattack on France's national tax authority triggered the Prime Minister to mandate a new dedicated cyber incident response capability
- The unit is government-focused but reflects a broader European trend of state-level cyber response formalization post-incident
- Timing coincides with EU CRA activation and elevates the political salience of enterprise cyber resilience across the EU regulatory landscape
📡 Macro Trends
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CyberScoop · Sep 09 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: The FBI releasing a new cyber strategy at the Billington Summit with explicit warnings that AI is materially improving adversary capabilities—while urging a return to fundamentals—provides CISOs with authoritative framing for board-level conversations about where to prioritize defensive investment.
- FBI released a new bureau-wide cyber strategy at the Billington CyberSecurity Summit tying AI-enhanced adversary capability to the need for cyber fundamentals
- Officials emphasized patching and basic hygiene over AI-driven security tooling as the most consequential defensive lever available now
- Remarks align with same-day FBI cyber chief comments on inadequate private sector threat information sharing, suggesting coordinated strategic messaging
🔓 Data Breach
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
BleepingComputer · Sep 08 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A fileless Linux rootkit injecting a PHP web shell directly into memory on F5 BIG-IP APM appliances—used by enterprises and financial institutions for access policy enforcement—evades disk-based detection and forensic scanning, requiring active threat hunting on a critical network perimeter device.
- Rootkit intercepts PHP file loading by Apache and injects a web shell into memory, leaving no trace on disk and bypassing file integrity monitoring
- F5 BIG-IP APM is a critical access control chokepoint for enterprise apps, APIs, and data across financial and government sectors
- Sophos analysis confirms the implant delivers on-demand server-side code execution identical to a traditional web shell without the detectability
⚖️ Governance & Policy
The EU CRA's Real Question: What Shipped, and When Did You Know?
BleepingComputer · Sep 08 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The EU Cyber Resilience Act's vulnerability reporting obligations take effect September 11—giving software vendors as little as 24 hours to report actively exploited flaws—creating immediate compliance exposure for any enterprise that ships software into EU markets.
- EU CRA vulnerability reporting requirements activate September 11, 2026 with a 24-hour mandatory disclosure window for actively exploited flaws
- Organizations must be able to definitively answer what software versions shipped and when a vulnerability was discovered to meet the requirement
- Non-compliance could trigger significant regulatory penalties; organizations without real-time SBOM and vulnerability tracking are acutely exposed
🚨 Critical Vulnerability
Microsoft Plugs Nearly 1,000 Security Holes
Krebs on Security · Sep 08 · Relevance: █████████░ 9/10
Why it matters to CISOs: A record 974-patch Patch Tuesday including two actively exploited zero-days and a publicly released bypass of last month's Defender patch demands immediate triage prioritization from every enterprise security team. AI-assisted vulnerability discovery is accelerating patch volumes faster than most teams can absorb.
- Microsoft's largest-ever single patch batch: 974 vulnerabilities, 119 rated critical, two actively exploited zero-days
- Anonymous researcher 'Nightmare Eclipse' released 'ShieldCrash' PoC bypassing last month's Microsoft Defender ShieldBreak patch hours after Patch Tuesday dropped
- Security experts warn organizations are struggling to test and deploy fixes at this volume, raising mean-time-to-patch risk
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
The Hacker News · Sep 09 · Relevance: █████████░ 9/10
Why it matters to CISOs: A CVSS 10.0 pre-authentication RCE in N-able N-central—widely used by MSPs managing enterprise endpoints—is being actively exploited and carries a CISA KEV deadline of September 11, making this an emergency patch priority for any organization using managed services or N-central directly.
- CVE-2026-86218 scored CVSS 10.0; unauthenticated remote code execution with no user interaction required
- CISA added to Known Exploited Vulnerabilities catalog with federal patch deadline of September 11, 2026
- N-central is broadly deployed across MSP environments, meaning a single compromise can cascade to dozens of enterprise clients
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
The Hacker News · Sep 09 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A maximum-severity unauthenticated RCE in SAP's kernel layer affecting EPP Processing poses existential risk to enterprises running SAP ERP environments—where compromise means full access to financial, HR, and supply chain data—and should trigger emergency patch prioritization outside normal cycles.
- CVE-2026-44756 scored CVSS 10.0; memory corruption flaw enabling unauthenticated remote code execution against SAP Extended Passport Processing
- Onapsis is urging immediate patching, citing severe impact on confidentiality, integrity, and availability of SAP systems
- SAP ERP systems are crown-jewel infrastructure at most large enterprises; pre-auth RCE at this severity warrants board-level awareness
Further Reading
- 🌍 Feds accuse China of ‘systematic’ distillation of U.S. AI models — CyberScoop
- 🌍 Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours — The Hacker News
- 🌍 France Establishes New Government-Focused Cyber Incident Response Unit — Infosecurity Magazine
- 📡 FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching — CyberScoop
- 🔓 Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit — BleepingComputer
- ⚖️ The EU CRA's Real Question: What Shipped, and When Did You Know? — BleepingComputer
- 🚨 Microsoft Plugs Nearly 1,000 Security Holes — Krebs on Security
- 🚨 N-able N-central Pre-Auth RCE Flaw Exploited in the Wild — The Hacker News
- 🚨 SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution — The Hacker News
Full Transcript
Click to expand full episode transcript
Alex: Welcome to Cleartext. It's Wednesday, September 9th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. Let's get into it.
Alex: We have a packed show today. The U.S. government is publicly accusing China of industrializing AI model theft. Google's threat intel group has documented autonomous AI agents harvesting thousands of credentials in under six hours. Microsoft just dropped the largest Patch Tuesday in history with nearly a thousand fixes. We've got two separate CVSS 10.0 vulnerabilities being actively exploited. The EU Cyber Resilience Act reporting requirements go live in two days. And the FBI is telling everyone to stop chasing shiny objects and patch their systems. Jordan, where do you want to start?
Jordan: Let's start where the strategic gravity is. The joint CISA, NSA, FBI advisory on Chinese AI model distillation. Because this isn't a story about a breach. This is a story about the systematic architecture of state-backed intellectual property extraction, and it has direct implications for every enterprise running API calls against frontier AI models.
Alex: Walk us through the mechanics.
Jordan: Chinese AI firms were routing millions of API requests across distributed accounts against Claude, GPT, Gemini, Grok, essentially every major U.S. frontier model. They're doing knowledge distillation at industrial scale. You send carefully crafted queries, you capture the outputs, and you use those outputs to train a smaller model that replicates the capabilities of the original. The advisory explicitly calls this the core of China's AI development strategy. Not a side hustle. Not opportunistic. The core.
Alex: And here's what should concern CISOs specifically. If your enterprise is consuming these models through shared or public APIs, your usage patterns, your prompts, the proprietary context you're injecting into those queries, all of that exists in the same infrastructure that was being systematically harvested. You may not be the target, but you're in the blast radius.
Jordan: Right. And the question isn't just whether the Chinese extraction campaigns touched your data. The question is whether your AI API access controls are even designed to detect anomalous query patterns at this scale. Most enterprises have barely gotten to the point of inventorying which teams are calling which models. The idea of monitoring for distillation-pattern activity? That's not on anyone's roadmap yet.
Alex: If you're briefing your board on AI risk this quarter, this advisory is exhibit A. It's not hypothetical. It's documented by three agencies with attribution. And it connects directly to the competitive value of whatever you're building on top of these models. If a state actor can replicate the model you're depending on, your differentiation evaporates.
Jordan: And speaking of AI as a weapon, let's talk about what Google's Threat Intelligence Group published. They documented a financially motivated group deploying an autonomous multi-agent AI framework that harvested thousands of credentials in fewer than six hours.
Alex: This is the one that should change how people think about their SOC.
Jordan: It should. Because the speed here isn't just faster humans. It's a qualitatively different attack model. Multiple AI agents coordinating autonomously, identifying targets, crafting approaches, extracting credentials, pivoting, all without a human operator making real-time decisions. Your SOC triage cycle, your MTTR benchmarks, your escalation playbooks, they were designed for human-speed adversaries.
Alex: If your detection-to-containment window is measured in hours and the attack completes in six, you're structurally incapable of responding. This is the moment where automated response isn't a nice-to-have. It's load-bearing infrastructure. And I know people have been hearing that for years, but the Google GTIG report puts real-world evidence behind it.
Jordan: Which connects perfectly to what the FBI said at Billington yesterday. They released a new bureau-wide cyber strategy, and the headline is almost painfully simple. AI is making adversaries materially better. Your best defensive investment right now is patching and basic hygiene. Not AI-powered defense tooling. Patching.
Alex: I actually appreciate the FBI being this blunt. Because there's a real risk in the market right now of security leaders chasing AI-driven defense capabilities while leaving fundamental gaps open. The FBI is essentially saying, the adversary is using AI to find and exploit the holes you already know about faster than you're closing them. So close them.
Jordan: It's not glamorous advice, but it's correct advice. And it dovetails with their criticism of private sector threat information sharing, which remains, in their words, inadequate. There's a coordinated message here: do the basics, and talk to us.
Alex: Let's stay on patching because the operational reality this week is brutal. Microsoft's September Patch Tuesday dropped 974 vulnerabilities. That's the largest single batch in the company's history. 119 rated critical. Two actively exploited zero-days.
Jordan: And within hours, a researcher going by Nightmare Eclipse released ShieldCrash, a proof-of-concept that bypasses last month's Defender patch for ShieldBreak. So you have teams that haven't even finished deploying August's fixes and the fix they prioritized is already being circumvented.
Alex: This is the structural problem the FBI is pointing at. The volume of patches is accelerating because AI-assisted vulnerability discovery is finding more flaws faster. But the human-intensive work of testing, staging, deploying, and validating patches hasn't gotten faster. The gap between discovery velocity and remediation velocity is widening.
Jordan: And your board needs to understand that gap in business terms. It's not a staffing problem. It's a physics problem. You can't test 974 patches in a week without breaking production systems. So the question becomes, what's your risk-based triage methodology, and is it good enough?
Alex: Which brings us to two CVSS 10.0 vulnerabilities that demand immediate attention. Jordan, take the N-able one first.
Jordan: CVE-2026-86218. Pre-authentication remote code execution in N-able N-central. No user interaction required. CVSS 10.0. Already being exploited in the wild. CISA added it to the Known Exploited Vulnerabilities catalog with a federal patch deadline of September 11, which is Thursday.
Alex: And the reason this is particularly dangerous is N-central's deployment footprint. It's the tool MSPs use to manage enterprise endpoints. A single compromised N-central instance can cascade to dozens of downstream client environments. If you use an MSP, you need to be on the phone with them today confirming they've patched.
Jordan: Not next week. Today. The exploitation is active. The attack surface is massive. And the supply chain amplification factor makes this one of the highest-consequence vulnerabilities we've seen this year.
Alex: The second CVSS 10.0 is CVE-2026-44756 in the SAP kernel. Memory corruption enabling unauthenticated remote code execution against SAP Extended Passport Processing. Onapsis is urging immediate patching.
Jordan: SAP systems are the crown jewels for most large enterprises. Financial data, HR records, supply chain operations, procurement. Pre-auth RCE at the kernel level means an attacker doesn't need credentials. They need network access to the SAP instance. If your SAP landscape is exposed, even internally, this is existential.
Alex: This should be patched outside your normal cycle. And yes, I said the board should know. Not because you want to alarm them, but because if you need an emergency change window and business owners push back, you want executive air cover already in place.
Jordan: Let's talk about the F5 BIG-IP story briefly because it's technically elegant and operationally nasty. Attackers are deploying a fileless Linux rootkit on F5 BIG-IP APM appliances. It intercepts PHP file loading by Apache, injects a web shell directly into memory. No disk artifacts. No file to detect. Your file integrity monitoring sees nothing.
Alex: BIG-IP APM is an access policy enforcement point. It sits at the perimeter controlling who gets into your applications and APIs. If that device is compromised with a fileless implant, you have an invisible backdoor at the front door. This requires active threat hunting, memory forensics, behavioral analysis. Passive scanning won't find it.
Jordan: Sophos confirmed the implant provides full on-demand server-side code execution. It's functionally identical to a traditional web shell with none of the detectability. If you're running BIG-IP APM, especially in financial services or government, hunt now.
Alex: Two more items before we wrap. France stood up a dedicated government cyber incident response unit after a major attack on their national tax authority. This is part of a broader European trend of formalizing state-level cyber response capabilities.
Jordan: It matters for CISOs because it's happening simultaneously with EU CRA activation. The political salience of cyber in Europe is at an all-time high. If you operate in EU markets, your regulatory counterparts are getting more capable and more demanding at the same time.
Alex: Which is the perfect segue. The EU Cyber Resilience Act's vulnerability reporting obligations take effect September 11. That is two days from now. If you ship software into EU markets, you have a 24-hour mandatory disclosure window for actively exploited vulnerabilities. You need to be able to answer definitively what version shipped and when you learned about the flaw.
Jordan: If you don't have real-time SBOM tracking and a vulnerability discovery timestamp you can defend in a regulatory proceeding, you are exposed. This isn't future risk. This is Thursday.
Alex: Alright, let's step back for the outlook. Jordan, what's the thread connecting everything today?
Jordan: Velocity. Every story today is about the gap between how fast things are moving and how fast organizations can respond. AI distillation at scale. Autonomous credential harvesting in six hours. A thousand patches in a single drop. CVSS 10s with two-day deadlines. 24-hour reporting obligations. The tempo of both offense and regulation has outpaced the operational capacity of most security organizations. And the honest answer is that tooling alone doesn't close that gap. You need architectural decisions about what you automate, what you accept, and what you escalate.
Alex: I'd add that the theme for board conversations this month is clear. The adversary's clock speed has changed. Your investment thesis needs to reflect that. Not by buying more AI tools, necessarily, but by ruthlessly prioritizing the fundamentals that reduce your exposure surface. The FBI said it plainly. The smartest thing you can do right now is patch.
Jordan: And verify your MSP patched. And hunt your BIG-IP appliances. And confirm your CRA reporting process is operational by Thursday.
Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. We're back tomorrow.
Jordan: Stay sharp.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-09.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.